CiberLATAMbywhalemate

Chile tightens customer authentication for transfers

Chile’s CMF is enforcing stronger customer authentication for transfers and digital payments, as fraud and identity theft risks rise.

Whalemate Labs · AI-assisted researchPublished:2 min read

Chile’s CMF has begun strictly enforcing its Customer Authentication standard for electronic transfers and digital payments. The move is aimed at digital fraud and identity theft, and reporting indicates that for most users it means phasing out the old plastic coordinate cards.

Chile’s CMF has begun strictly enforcing its Customer Authentication standard for electronic transfers and digital payments. The measure was presented as a response to digital fraud and identity theft, and reporting indicates that for most users it means giving up the traditional plastic coordinate cards.

What changes with ARC

According to coverage by El Mostrador, Customer Authentication becomes the standard for validating digital transactions in Chile’s banking system. The shift is meant to strengthen access to transfers and payments at a time when identity verification has become a sensitive point in the face of fraud attempts.

At the same time, public debate over these measures has played out alongside new warnings about vishing in Chile. The reporting reminded readers that banks must not ask by phone for secret PINs, transfer passwords, coordinate codes or transaction approvals. When that happens, the recommendation is to block the channels immediately and file a formal complaint with the institution.

Blocking and reporting incidents

The same coverage said financial institutions are required to keep 24/7 blocking channels available for cards, apps and web access. That point is central to incident response because customers do not have to wait for bank hours to stop an unauthorized access or a suspicious transaction.

Scotiabank Chile, for its part, publishes specific channels for reporting fraud and phishing, including an emergency phone line and a dedicated email address for phishing incidents. In its prevention materials, the bank also identifies attack types such as phishing, SIM swapping and skimming across its online channels.

The scheme rests on Law No. 20,009 and the reporting obligations before the CMF, which set the institutional response to digital banking fraud in Chile. In that structure, ARC appears as an additional layer of verification, while the complaint and 24/7 blocking channels serve as the immediate containment route once an incident has already occurred.

The coverage on vishing and Scotiabank’s alerts show how responsibilities are now divided among banks, the regulator and users, do not share credentials over the phone, cut off access as soon as an attempt is detected, and use the formal reporting channels that each institution must keep active.

Sources

View all